Total vulnerabilities in the database
In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as float Z = (1 - chroma.white.x - chroma.white.y) * Y / chroma.white.y;
and chroma.green.y * (X + Z))) / d;
but the divisor is not checked for a 0 value. A specially crafted file could trigger a divide-by-zero condition which could affect the availability of programs linked with OpenEXR.
Software | From | Fixed in |
---|---|---|
openexr / openexr | 3.1.2 | 3.1.2.x |
redhat / enterprise_linux | 7.0 | 7.0.x |
redhat / enterprise_linux | 6.0 | 6.0.x |
redhat / enterprise_linux | 8.0 | 8.0.x |
fedoraproject / fedora | 34 | 34.x |
fedoraproject / fedora | 35 | 35.x |
fedoraproject / fedora | 36 | 36.x |
debian / debian_linux | 10.0 | 10.0.x |
debian / debian_linux | 11.0 | 11.0.x |